Hello my name is Thomas Cope and for six years now I have been working as an Infrastructure and Security Specialist at IBM, while studying part time at Oxford University for a Masters Degree in Software and Systems Security. I am a programming and electronics enthusiast who enjoys working on projects in my spare time - you can learn more in the "Projects" sections below. I have a keen interest in Security, designing and building secure systems as well as performing pen tests on them. I enjoy "Capture the Flag" events and Security research. I am CISSP Certified as well as a Redhat System Engineer. I use theses skills extensively at work and for the support of this server which is used to hosts both myself and a friend's projects (Server Status). In my spare time I am a STEM Ambassador and an Associatsional (MBCS) Member of the British Computer Society. I play games such as TF2, Minecraft and Badminton, and enjoy Skiing when I get the chance. Feel free to drop me a line either on my Twitter or Linkedin. Plus I use GPG if you want to send me encrypted Mail (PubKey).
I have numerous ongoing projects all of which you can find out more below.
from Restricted user to root in one line
A short write up about a security vulnerability I discovered while working on a project which allows for an authenticated user to break out of the restricted HMC environment and elevate their permissions to root.
This is a demonstration of a proof of concept I built to tunnel ssh traffic over web-sockets. I build both a client and server application to achieve this.
A Proof of Concept of the Linux command 'scp' client side vulnerabilities (CVE-2019-6111 + CVE-2019-6110)
A CTF I took part in over the weekend
Interactive Linux Command Line Version of this site
Using a dynamic 'filesystem' both this site and the Linux command line version adapt their content to load new projects and pages. Its all quite overly complicated but it was fun to write :)
Toms Sentry Tracking Program
This is the 3rd incarnation on my Sentry Tracking program. Using opencv and C++, this project dynamically scans a webcam or video feed and tracks one or more targets
A in memory only, temporary file sharing service and API
I wanted to make a way to share files easily and a reason to learn memcached. This project is the combination of both.
An Example Website implementing good security practice for both HTTP Headers and SSL/TLS Configuration to provide a benchmark of what a secure web server configuration should look like.
Toms Very Basic Game
One of the largest program I've written. A simple space shooter written in C++ using OpenGL and a custom made game engine.
A helpful Arduino Library for polling Minecraft Servers
A custom made Arduino library to query a Minecraft server using the bespoke UDP query API.
Conference Call Bingo
A fun game to play while on a Conference Call.
Mass MQ Qload Converting Program
A tool to convert a large number of files into a more 'qload' friendly format. Written in C it's blazingly fast and easy to use.
Toms Vehicle Tracking System (Arduino GPS)
A Arduino based GPS and GRSM Tracking System using a custom built library for the Maplin GSMShield. The Arduino acquires a GPS lock, reads the value and sends the data encrypted via UDP to a collection server.
Fingerprint and Android Style Pattern Lock
A Arduino door lock using a Fingerprint scanner and a 7 inch touch screen.
A Arduino based portable HSM
A Arduino version of the Secure memory stick 'IronKey'. The Arduino acts as a HSM (Hardware Security Module) between the computer and the on board SD card shield. A Java app is used to send commands to Arduino. The Arduino enforces authentication and encryption using its on board EPPROM. After authentication, the Arduino encrypts and decrypts all of the data on the fly as it is written to a SD Card. After 10 incorrect password attempts the Arduino wipes its EPPROM destroying the Encryption key.
A snake style terminal screen saver written in Golang
A really simple terminal screen saver written in Golang.
Simple Programming Language Made in a Weekend
A really simple scripting like language made in a weekend. With dynamic variable allocation and cross platform support for Windows and Linux. My first C++ project to be completely cross platform using gcc and mingw.
Tails of Setting up this Server
Running this server has taught me a lot. Jenkins, Minecraft, MQTT, Mail, Nginx, KVM, HAProxy, PHP, Mysql and more.
A expansion on the orignal pastejacking attack using bash tricks
This is a demo of a new pastejacking attack using bash and command link tricks to fool the user into executing malicious code.
I make occasional posting on the IBM UK Apprentice Blog which you can check out here.
I have dabbled in many different programming languages and are keen to learn more. The list below covers the ones I use on a Frequent Basics...
- Visual Basic
Tools / Software:
- Forum Sentry
- Entrust PKI
- Network Manager
- Gemalto SafeNet Luna Network HSM
- OpenID Connect / OAuth / SAML
- LetsEncrypt / Certbot / Boulder
- JWT / JWE / JWS
- Hashicorp Vault
- Security Directory Server
- Security Access Manager
- HTTP Server
- Java Programming Language Java SE 6 - QA
- Advance Java OOP Threading and Serialization in Java OOP - QA
- C++ OOP - QA
- C# Threading, LINQ, Forms - QA
- IBM Badge - Get started with Kubernetes and IBM Cloud Container Service
- IBM Badge - Government Insights & Solutions (Silver)
- IBM Badge - Docker Essentials: Extend Your Apps With Containers
- IBM Badge - Mentor
- IBM Badge - Recognized Teacher/ Educator
- British Computer Society UK IT Apprentice of the Year 2015
- Apprentice of the Year 2015 (South East Region England)>
- Advance Apprentice of the Year 2014 (South Central Region England)
- World Skills Show UK Network Security Bronze Medal